citizenos / citizenos-fe

5 stars 2 forks source link

HC QUERY: Data security #183

Open BeccaMelhuish opened 1 year ago

BeccaMelhuish commented 1 year ago

@ilmartyrk @anettlinno For the HC texts, I'm assuming nothing changes with data storage/security as a result of the redesign?

Current guidance: https://citizenos.com/help/general/your-data-security/ Relevant text copied below


All your personal data is stored securely. The only data which will be accessible to those outside of our organisation is your activity in any public topics. Your activity in private topics will of course be visible to other participants of this topic, but no one else. Votes cast are visible only to topic admins, regardless of whether the topic is public or private.

Unlike some online platforms, we do not sell any of your data to third parties to raise funds. Citizen OS is funded via private philanthropic donations, EU grants and other grant funds.

To better understand our platform’s usage and improve its usability, we anonymously track certain elements of user activity via Plausible. Plausible is a lightweight and open source web analytics tool which uses no cookies and is fully compliant with data protection regulations around the world.

See our full Privacy and Cookies Policy for further information.

anettlinno commented 11 months ago

Triage 90. Data security remains the same also in redesign.

BeccaMelhuish commented 11 months ago

@anettlinno @ilmartyrk Thank you! One thing I would like to add to the HC which we missed off previously, and which is related to data privacy, is info about whether and to whom your email address gets displayed. I know on the current platform there is a way to opt in/out of having it displayed. Will it be the same on the redesign, and how will it work? (May be a question for Kevin, but will let you tag him if needs be) :)

BeccaMelhuish commented 11 months ago

I'm also wondering if we need to add anything about data with regard to social logins, I know there is usually a 'data cost' to users using them, so they may be wondering (or assuming worse that what is really the case on our platform).

BeccaMelhuish commented 11 months ago

Notes from meeting with Anett: Opt in and out of showing email address is still there. Yes, should write about it in HC under data security. It is default off. Explain it's for convenience if someone has a not easily recognisable username (e.g. many people with the same name). Re the social logins data question, need to find out about the Google logins - does @ilmartyrk know? Anett will also ask Kati.

ilmartyrk commented 11 months ago

@BeccaMelhuish not sure what you mean here, but we only request for minimal data like (user id. e-mail and profile image), also users usually get prompted by data providers (google, facebook) about what data we are requesting them to share on their first login atempt

BeccaMelhuish commented 11 months ago

Great - thanks @ilmartyrk, this is what I wanted to know :) Is it just user id. e-mail and profile image, or they're examples?

Also, does Google get any data (about the user's activity) in return for providing the login, or it's only in one direction? I had always understood there was usually some data gain in it for Google, in exchange for the service..